Privacy Policy

Effective Date: June 25, 2026  ·  Last Updated: September 29, 2026

1. Introduction

AdLume ("we," "us," "our") respects your privacy. This Privacy Policy explains what personal data and business data we collect, why we collect it, how we use it, and what rights you have when you use AdLume, Lumy, our website, application, integrations, communication workflows, and paid plans (together, the "Service").

Data Controller:
Marek Dąbrowski, conducting business as AdLume
NIP: 1133071063
ul. Stawki 2a/38, 00-193 Warsaw, Poland
Email: contact@adlume.co

This Policy is intended to support compliance with the General Data Protection Regulation (GDPR) (EU 2016/679), applicable Polish data protection law, and other privacy rules that may apply to our users.

This Policy does not replace any data processing agreement, platform-specific terms, or additional agreement we may sign with business customers.

2. Data We Collect

2.1 Account and Profile Data

When you create an account, buy a plan, contact us, or use the Service, we may collect:

2.2 Payment and Billing Data

Payments are processed by Stripe. We do not store your full credit card number. We may receive:

2.3 Connected Ad, Analytics, Marketing, and Ecommerce Data

When you connect or authorize Google Ads or Meta Ads, the Service may access and process data from those accounts. It may also process messages related to the Service in Slack. Additional advertising, analytics, tracking, marketing, or commerce tools may be supported later; this sentence does not imply they are available now.

Depending on the integration and permissions you approve, this may include:

We do not ask for your Google password or other third-party account passwords. Where available, access is granted and revoked through the provider's OAuth, API, workspace, or authorization system. Section 6 covers Google Ads and Meta Ads data in more detail.

2.4 Communication Tool Data

If you use Lumy inside Slack, we may process:

2.5 AI Input and Output Data

To provide AI-powered analysis and recommendations, we may process:

We do not intentionally send raw credentials, OAuth tokens, API keys, or payment card numbers to AI model providers.

2.6 Usage, Device, and Technical Data

We may automatically collect:

2.7 Website, Analytics, and Marketing Data

We may use analytics, advertising, and tracking tools such as GA4, PostHog, Meta Pixel, and similar tools to understand website usage, improve the Service, measure campaigns, and support marketing. Depending on your settings and consent requirements, this may include cookies, pixels, device identifiers, event data, page views, referral data, and campaign attribution.

If you subscribe to our newsletter or marketing communications, we may process your email address, preferences, sign-up source, campaign engagement, and related metadata through MailerLite.

2.8 Support and Communications Data

If you contact us by email, chat, form, social media, or another channel, we may retain the content of that communication, related metadata, and any follow-up actions.

3. How We Use Your Data

We use data to:

We also create aggregated and de-identified data from the data described above, including performance patterns, benchmarks, and records of which recommendations were accepted, rejected, or produced a measurable result. Such data is stripped of anything identifying you, your business, your accounts, or any individual, and may be combined with data from other customers to evaluate, benchmark, and improve the Service, including after your subscription ends. We do not disclose your data itself to other customers, and we do not publish benchmarks in a form that allows you or your accounts to be identified.

We do not sell your personal data.

4. Legal Bases for Processing

For users in the EU/EEA, UK, or other jurisdictions with similar legal basis requirements, we rely on the following bases:

PurposeData UsedLegal Basis
Providing the ServiceAccount data, connected tool data, communication data, AI inputs/outputsContract performance (Art. 6(1)(b))
Payments, renewals, refunds, invoicingPayment and billing dataContract performance (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Product security, abuse prevention, logsUsage, technical, security dataLegitimate interests (Art. 6(1)(f))
Product improvement and internal analyticsUsage data, feature data, support dataLegitimate interests (Art. 6(1)(f)) or consent where required
Website analytics and advertising pixelsCookies, event data, attribution dataConsent where required; legitimate interests where allowed
Marketing emailsEmail, preferences, engagement dataConsent (Art. 6(1)(a)) or legitimate interests where allowed for existing customer communications
Legal, tax, accounting, complianceBilling, contracts, support, logsLegal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f))

5. Third-Party Services and Processors

We use third-party service providers to operate the Service. They process data only for the purposes we authorize and subject to their own contracts, policies, and applicable law.

Provider / CategoryPurposeNotes
Google AdsConnected advertising account access and campaign dataScope depends on account authorization
Windsor.aiMeta Ads account connection, advertising data retrieval and approved changesCurrent connection path for existing Meta Ads customers; connected account data passes through this provider
Meta Ads (direct connection)Connected advertising account access, campaign data and approved changes, without an intermediaryBeing introduced alongside Windsor.ai; scope depends on the permissions you grant
Anthropic (via Amazon Bedrock)AI analysis of connected account data and recommendationsAccessed through Amazon Bedrock in the EU
Amazon Web Services (AWS)Application backend, database, logs, transactional email and Amazon Bedrock inferenceRegion eu-central-1 (Frankfurt, Germany)
StripePayments, subscriptions, refunds, invoices, tax and billing supportPayment card data is handled by Stripe
MailerLiteEmail marketing and newsletter communicationsUsed for opted-in or permitted email communications
SlackCommunication, approvals and notificationsOnly where enabled or connected
Analytics and advertising tools such as GA4, PostHog, Meta PixelWebsite/product analytics, attribution, performance measurement and remarketing where enabledConsent may be required depending on jurisdiction
CloudflarePublic website hosting, delivery, DNS, security and related web infrastructureUsed for the public website

6. Google API, Google Ads and Meta Ads Data Notice

6.1 Google API and Google Ads Data

When you connect Google services, our use and transfer of data received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, where applicable.

We use Google user data only to provide and improve user-facing features of the Service, including account analysis, recommendations, approved actions, reporting, monitoring, support, and security.

We do not use Google user data for:

We do not share Google Ads data except as needed to provide the Service, comply with law, protect security, or as described in this Policy.

You may revoke Google access through your Google Account settings or through the Service where supported.

6.2 Meta Ads Data

You can connect a Meta Ads account in one of two ways:

For a direct connection, you sign in on Meta's own screen and approve the permissions there. We never see your Facebook password. The direct connection asks for the ads_read, ads_management and business_management permissions.

After you pick an ad account, Lumy may read:

Changes to your campaigns. The ads_management permission lets Lumy change campaigns in your ad account. Lumy analyzes campaigns, proposes changes and executes them after your approval. In the direct connection, the only change available today is pausing or resuming a campaign. Each such change needs your confirmation, and Lumy first checks that the campaign belongs to the ad account you picked. Through Windsor.ai and Google Ads, Lumy makes a change after you approve it, or when you have turned on that type of change yourself in Lumy's permission settings.

Storage and retention. Meta gives us an access token for the direct connection. We store it, together with the selected account details, in our AWS database in Frankfurt (eu-central-1). The database encrypts stored data with AWS Key Management Service. We keep the token and account details while the connection is in place. Data Lumy reads from Meta is kept under the rules in Section 9.

Removing access and deleting data. You can remove AdLume's access at any time in your Facebook or Meta Business settings; for a Windsor.ai connection, remove Windsor.ai there. This stops new reads, but it does not delete data we already hold. To delete that data, follow Section 9.1 or our data deletion page.

7. AI Providers and Model Training

We may send relevant prompts, business context, account data, and user instructions to Anthropic, accessed through Amazon Bedrock in the EU, to generate outputs for the Service.

We do not intentionally send raw credentials, OAuth tokens, API keys, or payment card numbers to AI providers.

Your connected account data is not intentionally used to train general AI models for unrelated third-party use. Where an AI provider offers enterprise, API, or business data controls, we aim to use configurations that restrict provider training on customer data.

AI outputs may be incomplete, inaccurate, or inappropriate for your specific situation. Our Terms of Use explain your responsibility for reviewing, approving, and monitoring recommendations and automated actions.

8. International Data Transfers

We are based in Poland, but some providers and connected platforms may process data outside the EU/EEA, including in the United States.

Where required, we rely on appropriate transfer mechanisms such as:

Details of applicable transfer mechanisms are available on request where required by law.

9. Data Retention

We keep data only as long as reasonably necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law.

Data TypeTypical Retention
Account and profile dataWhile your account is active and for up to 2 years after closure or last activity, unless earlier deletion is required or requested
Free audit eligibility recordAby zapobiegać wielokrotnemu korzystaniu z bezpłatnego audytu, przechowujemy wyłącznie jednokierunkowo spseudonimizowany identyfikator workspace'u oraz informację i datę bezpłatnego audytu, które są automatycznie usuwane po 24 miesiącach.
To prevent repeated use of the free audit, we retain only a one-way pseudonymized workspace identifier and information about and the date of the free audit; these are automatically deleted after 24 months.
Connected ad, analytics, marketing, ecommerce, and communication dataWe retain connected-service data for as long as needed to provide the Service. When you use Lumy’s Google disconnect control, the defined local Google data is removed if the deletion process completes successfully; revoking access only in your Google Account settings does not currently trigger automatic deletion of local data. When you use Lumy’s Meta disconnect control on a Windsor.ai connection, we ask Windsor.ai to stop sharing that account and remove the Windsor.ai access key and account details from our records; data Lumy already read may remain until you delete your workspace. For a direct Meta connection, deleting your workspace removes the access token and selected account details. Removing AdLume's access only in your Facebook or Meta Business settings does not trigger automatic deletion of local data. Deleted database history may remain restorable in AWS backups for 35 days.
AI inputs, outputs, recommendations, approvals, and action logsWhile needed to provide history, auditability, support, security, and product improvement; typically up to two years unless otherwise agreed
Payment, invoice, tax, and accounting recordsAs required by Polish accounting and tax law, typically 5 years or longer if required
Website and product analyticsTypically up to two years, unless configured differently or anonymized
Marketing email dataUntil you unsubscribe or request deletion, subject to suppression lists and legal recordkeeping
Support and email communicationsTypically up to 3 years, unless needed for legal, security, or dispute purposes
Security logs and technical diagnosticsWe currently retain CloudWatch application logs for no longer than 30 days. Other diagnostic data may be retained for different periods where required for security, investigations, or compliance.

If you request deletion, we will delete or anonymize eligible data unless retention is required for legal, billing, security, fraud prevention, dispute resolution, or legitimate business purposes. Removing Lumy from Slack attempts to revoke the Google token and disconnects Slack, but it does not by itself delete retained local data. Slack disconnect still proceeds if Google revocation fails. After deletion, database history may remain restorable in AWS Point-in-Time Recovery for 35 days.

9.1 Deleting Your Data

These steps cover data from Google Ads, Meta Ads (through Windsor.ai or the direct connection), Slack and your workspace.

In the Lumy panel. The person who installed Lumy in the workspace can open the Lumy panel with the link Lumy sends in Slack, go to Settings, and in the Danger zone type the workspace name and choose Delete everything. Lumy then:

  1. cancels your paid plan, if you have one;
  2. asks Google to revoke Lumy's Google access;
  3. deletes the records stored for your workspace, then the workspace itself, including Google and Meta access tokens and account details;
  4. removes Lumy from your Slack workspace, where Slack allows it.

If deletion stops partway, the panel shows an error and some data may still exist. In that case, email us and we will finish the deletion by hand.

By email. Write to contact@adlume.co. Include the workspace name and the ad accounts the request covers. We may ask you to confirm that you can act for the workspace. We handle requests within the time limits set by the GDPR.

At Meta. Deleting data at AdLume does not remove AdLume's permission at Meta. To remove it, go to your Facebook or Meta Business settings and remove AdLume. For a Windsor.ai connection, remove Windsor.ai there as well.

What we keep. We keep invoices and tax records for as long as Polish law requires. Deleted database history may remain restorable in AWS backups for 35 days.

10. Cookies and Tracking

We use cookies and similar technologies to:

Types of cookies and similar technologies may include:

TypePurpose
EssentialAuthentication, security, session management, checkout, and core functionality
AnalyticsProduct and website usage analysis, diagnostics, performance measurement
Marketing / advertisingAttribution, remarketing, campaign measurement, audience building where allowed
PreferencesRemembering settings and interface choices

Where required by law, we ask for consent before using non-essential cookies or tracking technologies. You can also manage cookies through your browser settings. Disabling essential cookies may affect the functionality of the Service.

11. Your Rights

Depending on where you live, you may have rights to:

To exercise your rights, contact us at contact@adlume.co.

If you are in the EU/EEA and are not satisfied with our response, you may lodge a complaint with the Polish Data Protection Authority (UODO): https://uodo.gov.pl.

12. Marketing Communications

You may unsubscribe from marketing emails at any time using the unsubscribe link in the email or by contacting contact@adlume.co.

We may still send transactional or service-related messages, including account, billing, security, integration, policy, and support messages.

13. Security

We use technical and organizational measures designed to protect data, including:

No system is 100% secure. If we become aware of a personal data breach that creates a risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority where required by law.

14. Children's Privacy

The Service is not intended for individuals under 18. We do not knowingly collect personal data from minors. If we discover that we have collected data from a minor, we will delete it where required.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If changes are material, we will provide reasonable notice by email, in-app message, website notice, or another appropriate method.

The current version is available at https://adlume.co/privacy.

16. Contact

For privacy questions or rights requests:

Marek Dąbrowski, conducting business as AdLume
ul. Stawki 2a/38, 00-193 Warsaw, Poland
NIP: 1133071063
Email: contact@adlume.co
Website: https://adlume.co

This Privacy Policy was last reviewed on September 29, 2026.